PT-2020-19312 · Ge Healthcare · Apexpro Telemetry Server+3
Published
2020-01-24
·
Updated
2020-03-17
·
CVE-2020-6964
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ApexPro Telemetry Server versions 4.2 and prior
CARESCAPE Telemetry Server version 4.2 and prior
Clinical Information Center (CIC) versions 4.X and 5.X
CARESCAPE Central Station (CSCS) versions 1.X and 2.X
Description
The integrated service for keyboard switching in the affected devices could allow attackers to obtain remote keyboard input access without authentication over the network.
Recommendations
For ApexPro Telemetry Server versions 4.2 and prior, consider restricting network access to the integrated service for keyboard switching until a fix is available.
For CARESCAPE Telemetry Server version 4.2 and prior, restrict access to the keyboard switching service to prevent unauthorized input.
For Clinical Information Center (CIC) versions 4.X and 5.X, limit network exposure of the affected service to minimize the risk of exploitation.
For CARESCAPE Central Station (CSCS) versions 1.X and 2.X, disable the keyboard switching feature temporarily to prevent remote access without authentication.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apexpro Telemetry Server
Carescape Central Station
Carescape Telemetry Server
Clinical Information Center